SonarSource / SonarSource/sonar-xml

Dependency Dashboard

Open
#460 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
33
Forks
43
Avg merge
11h 8m
Merged PRs (30d)
23

Description

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.

Repository Problems

These problems occurred while renovating this repository. View logs.

  • ⚠️ WARN: Some release(s) did not have a releaseTimestamp, but as we're running with minimumReleaseAgeBehaviour=timestamp-optional, proceeding. See debug logs for more information

[!WARNING]
Renovate failed to look up the following dependencies: Failed to look up maven package org.sonarsource.xml:xml-its: no-result.

Files affected: its/plugin/pom.xml, its/plugin/test-plugin/pom.xml, its/ruling/pom.xml


Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

PR Closed (Blocked)

The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.

Detected Dependencies

github-actions (18)
.github/actions/orchestrator-cache/action.yml
.github/workflows/automated-release.yml
.github/workflows/build.yml (9)
  • actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7.0.1]
  • jdx/mise-action v4.3.0@c2a87611a18de5b3828c5652fe268e992400cb5c
  • actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7.0.1]
  • jdx/mise-action v4.3.0@c2a87611a18de5b3828c5652fe268e992400cb5c
  • actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7.0.1]
  • jdx/mise-action v4.3.0@c2a87611a18de5b3828c5652fe268e992400cb5c
  • jdx/mise 2026.9.6 → [Updates: 2026.9.9]
  • jdx/mise 2026.9.6 → [Updates: 2026.9.9]
  • jdx/mise 2026.9.6 → [Updates: 2026.9.9]
.github/workflows/cleanup-cache.yml
.github/workflows/mark-prs-stale.yml (1)
  • actions/stale v10.4.0@1e223db275d687790206a7acac4d1a11bd6fe629 → [Updates: v11.0.0]
.github/workflows/pr-cleanup.yml
.github/workflows/PrepareNextIteration.yml (1)
  • actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7.0.1]
.github/workflows/PullRequestClosed.yml
.github/workflows/PullRequestCreated.yml
.github/workflows/pvf-comment.yml
.github/workflows/releasability.yaml
.github/workflows/release.yml
.github/workflows/RequestReview.yml
.github/workflows/slack_notify.yml
.github/workflows/SubmitReview.yml
.github/workflows/ToggleLockBranch.yml
.github/workflows/unified-dogfooding.yml (3)
  • actions/checkout v7.0.0@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 → [Updates: v7.0.1]
  • jdx/mise-action v4.3.0@c2a87611a18de5b3828c5652fe268e992400cb5c
  • jdx/mise 2026.9.6 → [Updates: 2026.9.9]
.github/workflows/UpdateRuleMetadata.yml
maven (6)
its/plugin/pom.xml (3)
  • org.sonarsource.xml:xml-its 2.20.0-SNAPSHOT
  • org.awaitility:awaitility 4.3.0
  • org.apache.maven.plugins:maven-dependency-plugin 3.11.0
its/plugin/test-plugin/pom.xml (1)
  • org.sonarsource.xml:xml-its 2.20.0-SNAPSHOT
its/pom.xml
its/ruling/pom.xml (2)
  • org.sonarsource.xml:xml-its 2.20.0-SNAPSHOT
  • org.apache.maven.plugins:maven-dependency-plugin 3.11.0
pom.xml (23)
  • org.sonarsource.sonarlint.core:sonarlint-core-test-utils 11.10.0.86299
  • org.sonarsource.sonarqube:sonar-ws 26.9.0.129388
  • org.sonarsource.sonarqube:sonar-ws 26.9.0.129388
  • org.sonarsource.parent:parent 87.0.0.3057
  • org.sonarsource.api.plugin:sonar-plugin-api 14.0.0.4498
  • org.sonarsource.analyzer-commons:sonar-analyzer-commons 2.32.0.5319
  • org.sonarsource.api.plugin:sonar-plugin-api-test-fixtures 14.0.0.4498
  • org.sonarsource.analyzer-commons:sonar-xml-parsing 2.32.0.5319
  • org.sonarsource.orchestrator:sonar-orchestrator-junit5 6.4.3.4676
  • org.sonarsource.sonarlint.core:sonarlint-plugin-api 11.10.0.86299
  • org.sonarsource.sonarlint.core:sonarlint-core 11.10.0.86299
  • org.sonarsource.scanner.engine:plugin-api-scanner-impl 13.13.0.6016
  • org.sonarsource.scanner.engine:sensor-test-fixtures 13.13.0.6016
  • org.jetbrains.kotlin:kotlin-stdlib 2.4.20
  • com.google.code.findbugs:jsr305 3.0.2
  • org.sonarsource.analyzer-commons:sonar-analyzer-test-commons 2.32.0.5319
  • org.sonarsource.analyzer-commons:test-sonar-xml-parsing 2.32.0.5319
  • commons-io:commons-io 2.22.0
  • org.assertj:assertj-core 3.27.7
  • org.junit:junit-bom 6.1.3
  • org.mockito:mockito-core 5.23.0
  • com.google.code.gson:gson 2.14.0
  • org.apache.commons:commons-lang3 3.20.0
sonar-xml-plugin/pom.xml (4)
  • org.codehaus.mojo:license-maven-plugin 2.7.1
  • org.codehaus.mojo:exec-maven-plugin 3.6.4
  • org.apache.maven.plugins:maven-resources-plugin 3.5.0
  • org.apache.maven.plugins:maven-antrun-plugin 3.2.0
mise (1)
mise.toml (2)
  • java 21 → [Updates: 25]
  • maven 3.9

  • Check this box to trigger a request for Renovate to run again on this repository

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Dependency Dashboard documentation and inspect the affected files: .github/workflows/build.yml, mise.toml, pom.xml, and the listed integration-test POMs. Determine which dependency updates are actionable and how to resolve the failed lookup for org.sonarsource.xml:xml-its; done means the dashboard can be regenerated without unresolved repository problems.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, java
Domain
build-system, ci-cd, devops
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.